Weaknesses of type CWE-668

235 results

Divulgação de informações

O software expõe dados sensíveis (credenciais, tokens, dados pessoais, configs internas) a uma entidade não autorizada — seja por acesso direto, mensagens de erro verbosas, logs mal protegidos ou canais inseguros. É a falha de um controle de acesso ou encriptação que deveria manter esses dados privados.

Example

Uma API REST que retorna a senha do usuário em plain text na resposta de login; ou um servidor que deixa arquivos de backup (.sql, .env) acessíveis via web; ou um log de erro que exibe URLs internas e tokens de autenticação em páginas públicas.

How to mitigate

Classifique dados por sensibilidade, nunca exponha em respostas de erro ou logs públicos. Use encriptação em trânsito (TLS) e em repouso, aplique controle de acesso rigoroso aos arquivos sensíveis, e revise regularmente o que seu código imprime em mensagens e registros.

CVE-2023-27976HIGH A CWE-668: Exposure of Resource to Wrong Sphere vulnerability exists that could cause remote code execution when a valid user visits a maliEPSS 0.8%CVE-2022-38599MEDIUMTeleport v3.2.2, Teleport v3.5.6-rc6, and Teleport v3.6.3-b2 was discovered to contain an information leak via the /user/get-role-list web iEPSS 0.8%CVE-2022-39015Under certain conditions, BOE AdminTools/ BOE SDK allows an attacker to access information which would otherwise be restricted.EPSS 0.8%CVE-2021-30153MEDIUMAn issue was discovered in the VisualEditor extension in MediaWiki before 1.31.13, and 1.32.x through 1.35.x before 1.35.2. . When using VisEPSS 0.8%CVE-2023-45911CRITICALAn issue in WIPOTEC GmbH ComScale v4.3.29.21344 and v4.4.12.723 allows unauthenticated attackers to login as any user without a password.EPSS 0.8%CVE-2026-44009CRITICALvm2: Sandbox Breakout Through Null Proto ExceptionEPSS 0.8%CVE-2023-25409HIGHAten PE8108 2.4.232 is vulnerable to Incorrect Access Control. Restricted users have access to other users outlets.EPSS 0.8%CVE-2023-37911MEDIUMorg.xwiki.platform:xwiki-platform-oldcore may leak data through deleted and re-created documentsEPSS 0.8%CVE-2022-45895MEDIUMPlanet eStream before 6.72.10.07 discloses sensitive information, related to the ON cookie (findable in HTML source code for Default.aspx inEPSS 0.7%CVE-2019-1848CRITICALCisco DNA Center Authentication Bypass VulnerabilityEPSS 0.7%CVE-2024-22281HIGHApache Helix Front (UI): Helix front hard-coded secret in the express-sessionEPSS 0.7%CVE-2020-12142MEDIUMIPSec UDP key material can be retrieved from EdgeConnect by a user with admin credentialsEPSS 0.7%CVE-2022-2882MEDIUMAn issue has been discovered in GitLab CE/EE affecting all versions starting from 12.6 before 15.2.5, all versions starting from 15.3 beforeEPSS 0.7%CVE-2020-22647CRITICALAn issue found in DepositGame v.1.0 allows an attacker to gain sensitive information via the GetBonusWithdraw and withdraw functions.EPSS 0.7%CVE-2026-34538MEDIUMApache Airflow: Authorization bypass in DagRun wait endpoint (XCom exposure)EPSS 0.7%CVE-2020-15215MEDIUMContext isolation bypass in ElectronEPSS 0.7%CVE-2022-31596MEDIUMUnder certain conditions, an attacker authenticated as a CMS administrator and with high privileges access to the Network in SAP BusinessObjEPSS 0.7%CVE-2026-28779HIGHApache Airflow: Path of session token in cookie does not consider base_url - session hijacking via co-hosted applicationsEPSS 0.7%CVE-2026-54504HIGHMCP Documentation Server: Web UI API binds to all interfaces without authentication by defaultEPSS 0.7%CVE-2026-45077HIGHSymfony: Unauthenticated PHP Object Deserialization in MonologBridge server:log ListenerEPSS 0.7%